-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2023-36665 - Fix not reflected in dist version #1918
Comments
Following. Scanning tools still detect protobufjs 7.2.4 as containing CVE-2023-36665 because the fix for this vulnerability was only applied to the sources ( |
Any update? |
BTW, I'm still getting CVE-2023-36665 as a security vulnerability from protobufjs@6.11.4, even when I see the code change in the dist files: https://cdn.jsdelivr.net/npm/protobufjs@6.11.4/dist/protobuf.js Furthermore, the affected version range here https://nvd.nist.gov/vuln/detail/CVE-2023-36665 show as if everything below 7.2.4 is vulnerable. |
That's weird, because the dist files are supposed to be rebuilt in the In any case, in the latest versions (7.2.5 and 6.11.4) the dist files are fixed, I checked both of them. The GitHub advisory GHSA-h755-8qp9-cq85 was updated to list 6.11.4 as fixed. If anyone knows how to update the advisory at https://nvd.nist.gov/vuln/detail/CVE-2023-36665 accordingly, please let me know, or just go ahead and do it. |
I'm still getting CVE-2023-36665 detected in 7.2.5. |
I believe CVE’s can be updated through here : https://www.cve.org/ReportRequest/ReportRequestForNonCNAs I won’t be able to get the update in till next mid week. If no one has done it by then I will go ahead and request the update. |
Accidentally closed with comment. Reopening till CVE is updated. |
Is there any news on this? I'm still getting report from scanning tools 😭 |
CVE has been updated to to correctly identify 7.2.5 as the fixed version : https://nvd.nist.gov/vuln/detail/CVE-2023-36665. Marking this issue as closed. |
protobuf.js version: 7.2.4
Expected Behavior : Fix introduced for CVE-2023-36665 (https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.2.4) would also be reflected in the distribution version of the code as well
Actual Behavior : Fix does not seem to be rolled out to distribution version. Distribution version seems to be last compiled on September 9 2022 - https://cdn.jsdelivr.net/npm/protobufjs@7.2.4/dist/protobuf.js
Code snippet from https://cdn.jsdelivr.net/npm/protobufjs@7.2.4/dist/protobuf.js
Would expect below to match e66379f
The text was updated successfully, but these errors were encountered: